project-stage-detect

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate file system analysis to determine project status. All activities are confined to the local project environment and match the intended purpose.
  • [COMMAND_EXECUTION]: Uses standard utilities such as Bash, Glob, and Grep for scanning project structures and counting files. No evidence of shell injection or arbitrary command execution was detected.
  • [DATA_EXPOSURE]: Accesses project-related files in directories like design/, src/, and production/. It does not target sensitive system locations (e.g., .ssh, .aws) or environment variables, and lacks network capabilities to exfiltrate data.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect injection as it processes untrusted project files.
  • Ingestion points: Analyzes content from files within design/, src/, production/, and prototypes/ using the Read and Grep tools.
  • Boundary markers: Absent; the skill does not explicitly delimit untrusted file content from its own instructions.
  • Capability inventory: Uses Read, Glob, Grep, and Bash. It has the ability to write a markdown report to the production/ directory.
  • Sanitization: Absent; content is analyzed as-is.
  • Mitigation: The risk is significantly reduced by the 'Collaborative Protocol', which forces the agent to ask for user approval before taking any action (such as writing a report) based on its findings.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — project-stage-detect